GUÍA de sociedad

Provider vs Deployer Under the EU AI Act

The EU AI Act defines a provider by development and market or service placement under its name, while a deployer uses an AI system under its authority in a professional context.

  • 3 minutos de lectura
  • Última actualización
En esta pagina3 minutos de lectura
  1. Descripción general
  2. Buceo profundo
  3. Impacto Estratégico
  4. The Future of Provider vs Deployer Under the EU AI Act
  5. Implementación en el mundo real
  6. Riesgos y barandillas
  7. Hoja de ruta de implementación
  8. Sigue explorando
  9. Preguntas frecuentes

Descripción general

The role is determined by the actual activity and can change when an organization relabels or substantially modifies a high-risk system.

Buceo profundo

The EU AI Act distinguishes a provider from a deployer. Under Article 3, a provider develops an AI system or has one developed and places it on the market, or puts it into service, under its own name or trademark. A deployer uses an AI system under its authority in a professional context; personal non-professional use is excluded. These roles do not simply mean vendor and customer. A business that commissions development and markets the system under its own name may be the provider; an organization using a purchased tool for work may be a deployer. One organization can hold different roles across systems. Importers, distributors, product manufacturers, and authorized representatives have separate roles. Article 25 can reassign provider duties to a distributor, importer, deployer, or another third party in specified cases: branding a high-risk system, substantially modifying it while it remains high-risk, or changing its intended purpose so it becomes high-risk. A user-interface change alone is not automatically a substantial modification. Under the 2026 AI Omnibus, when a role change occurs the initial provider generally ceases to be provider of that system but must cooperate with the new provider and supply necessary information, reasonable technical access, and assistance, including known limitations and failure modes. This duty does not apply if the initial provider clearly specified the system must not be changed into a high-risk system. The parties must agree in writing on needed support. Provider and deployer duties depend on the system and role. For high-risk systems, providers handle conformity and required documentation; deployers use the system according to instructions and assign competent human oversight. The Act has applied generally since August 2, 2026, with phased rules: Annex III high-risk system rules apply from December 2, 2027, and Annex I product-embedded rules apply from August 2, 2028. Check the current Regulation for the specific system and use.

Impacto Estratégico

Riesgo y seguridad

Los daños catastróficos y cotidianos de la IA dependen de quién comprende los riesgos y quién puede actuar.

Decisiones más claras

La alfabetización pública y profesional determina si es políticamente posible una política de seguridad sólida.

Cortando el bombo

Las explicaciones claras reducen la captación por la exageración, las relaciones públicas de laboratorio y el vago teatro de ética.

The Future of Provider vs Deployer Under the EU AI Act

The AI Act’s provider and deployer roles may overlap across a product supply chain, and the 2026 AI Omnibus changed both Article 25 cooperation duties and the timing of high-risk system rules. Annex III rules apply from 2 December 2027 and Annex I product-embedded rules from 2 August 2028. Keep role assessments tied to each system version and intended purpose, and review them when branding, modifications, or uses change. Check the current consolidated Regulation and Commission guidance at each launch.

Implementación en el mundo real

A software company that develops a system and places it on the EU market under its own name assesses provider duties.

A hospital that uses a vendor’s AI system under its authority assesses deployer duties alongside healthcare and data-protection rules.

A reseller that changes a system’s purpose or makes a substantial modification checks whether Article 25 shifts provider obligations to it.

A group that commissions a system under its own brand checks the provider definition even when an outside firm performed development.

Riesgos y barandillas

  • Tratar el riesgo existencial como ciencia ficción mientras que la capacidad se agrava.

  • Confundir la seguridad del producto superficial con la alineación en condiciones de alta autonomía.

  • Dejando a las audiencias que no hablan inglés ni a expertos solo con fuentes de baja calidad.

Hoja de ruta de implementación

  1. Separe los riesgos de daños al producto, mal uso y pérdida de control/desalineación.

  2. Pregunte qué evidencia cambiaría su opinión sobre los plazos y la gravedad.

  3. Prefiera fuentes primarias y evaluaciones concretas a afirmaciones de marketing.

  4. Identifique un camino de acción: carrera, política, financiamiento o habilidades, no solo concientización.

Sigue explorando

Free newsletter

Get the daily AI briefing

Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.

One email each weekday. Unsubscribe in one click. We never sell or share your address.

Test yourself

Take the Provider vs Deployer Under the EU AI Act quiz

Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.

Iniciar prueba

Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation

Preguntas frecuentes

What is Provider vs Deployer Under the EU AI Act?

The EU AI Act defines a provider by development and market or service placement under its name, while a deployer uses an AI system under its authority in a professional context. The role is determined by the actual activity and can change when an organization relabels or substantially modifies a high-risk system.

Under Article 3, which activity most directly describes a provider?

The provider definition concerns development and placement or putting into service under the provider’s own name or trademark.

Which activity most directly describes a deployer?

Article 3 defines a deployer as an organization or person using an AI system under its authority, excluding personal non-professional use.

A company commissions a system and markets it under its own brand. Which role should it assess?

The provider definition includes a party that has a system developed and places it under its own name or trademark.

When may Article 25 treat a deployer or distributor as the provider of a high-risk system?

Article 25 lists specific provider-requalification circumstances, including branding and certain substantial modifications.

What determines whether an organization is a provider or deployer?

The statutory definitions depend on what the organization actually does in the system lifecycle.